Build the foundation • New ZealandRead the Australia version

How to Build a New Zealand AML/CFT Programme

A plain-English guide to establishing, implementing, maintaining and reviewing a New Zealand AML/CFT programme.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. The Programme Has Four Jobs
  3. Key words explained
  4. Part 1: What the Programme Should Cover
  5. Part 2: Build It in the Right Order
  6. Part 3: What Good Evidence Looks Like
  7. Part 4: Maintain and Review the Programme
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

An AML/CFT programme is the written set of procedures, policies and controls used to detect, manage and reduce the ML/TF risks identified in the business’s risk assessment.

The programme must be based on the risk assessment, put into use and kept current. A document alone is not an implemented programme.

At a glance

The Programme Has Four Jobs

  • Follow the risk

    Controls should respond to the risks identified in the written risk assessment.

  • Cover the duties

    CDD, reporting, records, monitoring, people and other required areas should be addressed.

  • Guide daily work

    Staff should be able to tell what to do, when to do it and where to record it.

  • Improve over time

    Reviews, audit findings, incidents and business changes should feed back into the programme.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

AML/CFT programme
The written procedures, policies and controls used to detect, manage and reduce the business’s ML/TF risks.
Reporting entity
A person or business that has duties under the AML/CFT Act for a covered activity.
Procedure
The steps a person follows to complete an AML/CFT task.
Control
A safeguard such as a check, approval, alert, limit or report.
Risk-based
Using stronger effort where risk is higher while still meeting every mandatory duty.

What the Programme Should Cover

  • Vetting and training for senior managers, the compliance officer and staff doing AML/CFT work.
  • Standard, simplified and enhanced CDD, including delayed verification and reliance rules.
  • Ongoing CDD, customer risk ratings and account or activity monitoring.
  • Suspicious activity and prescribed transaction reporting.
  • Keeping, protecting and disposing of AML/CFT records.
  • Examining complex, unusually large or unusual patterns of activity.
  • Controls for countries, products, delivery methods, anonymity and new technology.
  • Internal communication, compliance monitoring, review and independent audit.

Build It in the Right Order

  1. Step 1

    Confirm the business is covered

    Record the activities that make the business a reporting entity and any territorial or ordinary-course issue.

  2. Step 2

    Complete the risk assessment

    Assess customers, countries, products, services, transactions and delivery channels, using current national and sector information.

  3. Step 3

    Turn risk into controls

    For each important risk, set out who acts, what they do, when it happens, the evidence kept and the approval needed.

  4. Step 4

    Build in every legal duty

    Check the programme against sections 56 and 57 and current DIA guidance so that no required area is missed.

  5. Step 5

    Implement and test

    Train the right people, update systems and forms, test sample work and correct anything that does not work.

What Good Evidence Looks Like

Examples that show the programme is in use
AreaEvidenceSimple test
CDDFiles, verification, ownership and risk decisionsCan another trained person follow the decision?
MonitoringAlerts, reviews and written findingsAre unusual patterns examined promptly?
ReportingEscalations, decision notes and goAML receiptsCan the three-working-day deadline be proved?
PeopleVetting, training and competency recordsDo staff know what their role requires?
ReviewVersions, change records and audit actionsDoes the programme change when risk changes?

Maintain and Review the Programme

The risk assessment and programme should be reviewed regularly and when the business or its risks change. New products, technology, countries, customer types, delivery methods, findings and legal changes are common triggers.

A review should ask whether the written control remains adequate and effective, whether staff use it and whether it produces the expected result.

Independent audit

The programme and risk assessment are generally subject to an independent audit every three years, unless DIA gives a four-year timeframe or requests another time. High-value dealers have a different audit rule.

Common Mistakes

  • The programme repeats the Act but does not explain the business’s process.
  • Controls do not match the risks in the risk assessment.
  • CDD responsibilities are split across teams without a clear handover.
  • Exceptions are allowed but no approval or record is required.
  • Staff are trained on policy wording but not on realistic cases.
  • An audit finding is closed by changing a document only.

Common Questions

Short answers to the questions businesses ask most often.

Must the programme be in writing?

Yes. It must be written, based on the risk assessment and include adequate and effective procedures, policies and controls.

Who administers and maintains the programme?

The reporting entity must appoint a compliance officer to administer and maintain it. Senior managers and the wider business still have responsibilities.

Can a small business use a short programme?

It can be proportionate and easy to use, but it must still cover every duty that applies and respond to the business’s actual risks.

Can work be outsourced?

Some tasks may be outsourced, but the reporting entity keeps responsibility. Access, instructions, privacy, quality checks and evidence should be addressed.

When should the programme be updated?

Update it when risk, operations, law or findings show that a control is no longer adequate or effective. Do not wait for the next scheduled review.

Official Sources

This guide cites the following sources.

  1. Primary lawNew Zealand Legislation
    Anti-Money Laundering and Countering Financing of Terrorism Act 2009

    The current New Zealand AML/CFT Act, including CDD, programme, reporting, audit and record duties.

  2. Regulator guidanceDepartment of Internal Affairs
    AML/CFT Programme Guidance 2026

    Current guidance on establishing, implementing, maintaining and reviewing an AML/CFT programme.

  3. Regulator guidanceDepartment of Internal Affairs
    AML/CFT information and guidance

    DIA’s current AML/CFT homepage, including guidance for reporting entities and its consolidated supervision role from 1 July 2026.

  4. Regulator guidanceDepartment of Internal Affairs
    Audit Guidance for Risk Assessment and AML/CFT Programme

    Current guidance on audit timing, independence, scope, evidence and reporting.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your New Zealand business does and where the uncertainty sits. We will help you work out the practical AML/CFT response.

Tell us about your situation